Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent) - deep enough to read controls, understand risk, and challenge a requester's draft. Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).